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DETAILED ACTION 

1 . This Office Action is in response to tine most recent papers filed on June 6, 2008. 

2. Claims 1 , 3-30 & 32-81 are pending. 

3. Claims 2 & 31 are canceled. 

4. Claims 1, 3, 13, 15, 19, 29, 30, 32, 58-60, 69, & 78-81 are amended. 

5. Claims 1 , 3-30 & 32-81 are rejected. 



Response to Arguments 

6. Applicant's arguments filed March 4, 2008 have been fully considered but they 
are not persuasive. 

Applicant argued in substance that "Thompson teaches a single communication 
to transfer encrypted data to a device, rather than authenticating authorization to access 
data on an implantable medical device by securely retrieving the crypto key and 
transacting a data exchange session using a crypto key by transitioning to a long range 
interface." 

See (Thompson, Figure 4 
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The route for distribution of the keys by the key source (See Examiner marl< 1 
area) is the functional equivalent of the use of a short range or secure and is a first 
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communication. The transmission route of the encrypted data (See Examiner marl< 2 
area) is a second communication on a long range or unsecured interface. 



Claim Rejections - 35 USC § 101 

7. 35 U.S.C. 101 reads as follows: 

Whoever invents or discovers any new and useful process, machine, 
manufacture, or composition of matter, or any new and useful improvement thereof, 
may obtain a patent therefor, subject to the conditions and requirements of this title. 

Claims 1-29, 60-68 and 79 are non-statutory because they recite a computer 
program per se representing functional descriptive material without a memory and a 
processor or claim language clearly claiming a hardware invention. 

Claim Rejections - 35 USC § 102 

8. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that 
form the basis for the rejections under this section made in this Office action: 

A person shall be entitled to a patent unless - 

(e) the invention was described in (1) an application for patent, published under section 122(b), by 
another filed in the United States before the invention by the applicant for patent or (2) a patent 
granted on an application for patent by another filed in the United States before the invention by the 
applicant for patent, except that an international application filed under the treaty defined in section 
351(a) shall have the effects for purposes of this subsection of an application filed in the United States 
only if the international application designated the United States and was published under Article 21(2) 
of such treaty in the English language. 
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9. Claims 1, 3, 5-10, 17-20, 27-30, 32, 34-39, 46-49, 56-61, 68-70 & 77-81 are 
rejected under 35 U.S.C. 102(e) as being anticipated by United States Patent No.: 
7,027,872 B2 (Thompson). 

As Per Claim 1: Thompson teaches: 

A system for securely authenticating a data exchange session with an implantable 
medical device, comprising: 

- a secure key repository to maintain a crypto key uniquely associated with an 
implantable medical device to authenticate data during a data exchange session 

(Thompson, Column 8, Lines 18-50 "FIG. 4 is a block diagram illustrating one 
embodiment of a secure data transfer structural scheme in accordance with the present 
invention, shown generally at 220. In this embodiment, sensitive information 221 (such 
as patient information) is transferred in encrypted form from IMD any one of the 
programmers and instruments (1 12, 1 14, 1 16) or similar remote device to remote expert 
data center or clinician computer 122 across data communications media/connection 
226. While a representative use of the present invention is illustrated using 
communications between Programmer (112, 114, 116) and clinician computer 122, any 
combination of clinician devices, IMD interface devices, central database or expert 
system servers, medical device personnel personal computers or servers, and patient 
monitoring equipment, or any other data transmission device may be used in 
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accordance with tlie present invention. In the illustrative example, Programmer (112, 
114, 116) may be any instrument capable of obtaining, storing, and transmitting medical 
and administrative information, including sensitive information 221. Programmer (112, 
114, 116) is capable of being coupled to one or more IMDs 132. IMD 132 obtains 
certain information, possibly including sensitive information 221 from the patient, then 
transfers the patient information to programmer (112, 114, 116). Data communication 
media 226 could be configured to include a telephone line connection, a direct network 
connection, an intranet connection, an internet connection, wireless LAN, fiber optic 
network a satellite connection, a laser or infrared system, any other suitable network 
protocol connection, or a combination thereof. 

Key source 228 provides both programmer (112, 114, 116) and clinician 
computer 122 with encryption/decryption keys for encrypting/decrypting sensitive 
information 221 ."). 

A device maintaining an encryption/decryption key has a repository for it. 

- an external device to establish a secure connection through a short range 
Interface with the secure key repository, to authenticate authorization to access 
data on the implantable medical device by securely retrieving the crypto key from 
the secure key repository 

(Thompson, Column 8, Lines 48-59 "Key source 228 provides both programmer 
(112, 114, 116) and clinician computer 122 with encryption/decryption keys for 
encrypting/decrypting sensitive information 221 . In one embodiment of the invention, 
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key source 228 distributes symmetric encryption/decryption keys. In another 
embodiment of the invention, key source 228 distributes asymmetric keys (i.e., 
pubic/private keys). If the encryption/decryption algorithms employed by the invention 
are standard algorithms known to the public, additional security measures must be 
taken in the disbursement of the keys from key source 228 to programmer (112, 114, 
1 1 6) and 1 22 in order to ensure privacy."). 

- to transact the data exchange session using the crypto key to authenticate the 
data by transitioning to a long range interface 

(Thompson, Column 9, Lines 10-16 "Before sensitive information 221 is 
transmitted across data communication media 226, sensitive information 221 is 
encrypted by encryption engine 230. Encryption engine 230 may be implemented in 
hardware or software, although may preferably be implemented in software to allow for 
ease of upgrades to different algorithms, key lengths, and key variation."). 

(Thompson, Figure 4 
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The route for distribution of the keys by the key source (See Examiner marl< 1 
area) is the functional equivalent of the use of the "short range interface". The 
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transmission route of the encrypted data (See Examiner marl< 2 area) is the functional 
equivalent of the "long range interface". 

As Per Claim 3: The rejection of claim 1 is incorporated and further Thompson teaches: 

- an authentication component to employ the crypto key during the data 
exchange session, comprising at least one of: 

- a command authenticator to authenticate commands exchanged through the 
external device with the implantable medical device and 

(Thompson, Column 4, Lines 23-48 wherein medical device program commands" 
are encrypted and sent to the IMD). 

- a data integrity checker to check the integrity of the data received by and 
transmitted from the external device 

(Thompson, Column 4, Lines 49-66 message integrity checks). 

- a data encrypter to encrypt the data received by and transmitted from the 
external device 

(Thompson, Figure 4 both the Programmer and the Clinician computer have 
encryption engines and decryption engines). 

As Per Claim 5: The rejection of claim 1 is incorporated and further Thompson teaches: 
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- a key generator to statically generate the crypto key, and to persistently store 
the crypto key in the secure key repository 

(Thompson, Figure 4 l<ey source 228, and column 8 lines 48-66, the key source 
distributes symmetric keys). 

As Per Claim 6: The rejection of claim 5 is incorporated and further Thompson teaches: 

- the crypto key is stored on at least one of the implantable medical device, a patient 
designator, a secure database, a physical token, and a repeater. 

(Thompson, Figure 4 key source 228, and column 8 lines 48-66, the key source 
distributes symmetric keys and asymmetric keys to the programmer and clinician 
computer, both would have a secure database and designate patients). 

As Per Claim 7: The rejection of claim 5 is incorporated and further Thompson teaches: 

- the crypto key is securely retrieved from the secure key repository through a 
programmer 

(Thompson, Figure 4 key source 228, and column 8 lines 48-66, the key source 
distributes symmetric keys and asymmetric keys to the programmer and clinician 
computer). 
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As Per Claim 8: The rejection of claim 1 is incorporated and further Thompson teaches: 

- a key generator to dynamically generate the crypto key 

(Thompson, Figure 4 key source 228, and column 8 lines 48-66 and column 910- 
49; the key source distributes many different kind of algorithms including the generation 
of session keys). 

As Per Claim 9: The rejection of claim 8 is incorporated and further Thompson teaches: 

- the crypto key is stored on at least one of the implantable medical device, a 
patient designator, and a repeater 

(Thompson, Figure 4 key source 228, and column 8 lines 48-66, the key source 

distributes symmetric keys and asymmetric keys to the programmer and clinician 
computer, both would have a secure database and designate patients). 

As Per Claim 10: The rejection of claim 8 is incorporated and further Thompson 
teaches: 

- the crypto key is securely retrieved from the secure key repository through at 
least one of a programmer and a repeater 
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(Thompson, Figure 4 key source 228, and column 8 lines 48-66, the key source 
distributes symmetric keys and asymmetric keys to the programmer and clinician 
computer, both would have a secure database and designate patients). 

As Per Claim 17: The rejection of claim 1 is incorporated and further Thompson 
teaches: 

- a secure database to maintain the crypto key 

(Thompson column 8 lines 18-47 teaches a secure database). 

- a secure server providing the crypto key through a secure connection 

(Thompson column 9 lines 10-49 teaches a tunneled connection). 

As Per Claim 18: The rejection of claim 17 is incorporated and further Thompson 
teaches: 

- the secure connection comprises at least one of a serial or hardwired 
connection and a secure network connection 

(Thompson column 9 lines 63-67 and column 10 lines 1-10 teach hardwired 
secure connection). 
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As Per Claim 19: The rejection of claim 17 is incorporated and further Thompson 
teaches: 

- the external device comprises a programmer 

(Thompson, Figure 4 key source 228, and column 8 lines 48-66, the key source 
distributes symmetric keys and asymmetric keys to the programmer and clinician 
computer). 

As Per Claim 20: The rejection of claim 19 is incorporated and further Thompson 
teaches: 

- the crypto key is provided from the programmer to a repeater 

(Thompson, Figure 4 key source 228, and column 8 lines 48-66, the key source 
distributes symmetric keys and asymmetric keys to the programmer and clinician 
computer). 

As Per Claim 27: The rejection of claim 1 is incorporated and further Thompson 
teaches: 

- the crypto key comprises at least one of a 128-bit crypto key and a symmetric 
crypto key 
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(Thompson column 9 lines 50-64 teaches "a 128 bit hashed representation of a 
message" and a public key). 

As Per Claim 28: The rejection of claim 1 is incorporated and further Thompson 
teaches: 

- the crypto key comprises at least one of a statically generated and persistently 
stored crypto key, dynamically generated and persistently stored crypto key, a 
dynamically generated and non-persistently stored session crypto key 

(Thompson, Figure 4 key source 228, and column 8 lines 48-66, the key source 
distributes symmetric keys and asymmetric keys to the programmer and clinician 
computer, both would have a secure database and designate patients). 

As Per Claim 29: The rejection of claim 1 is incorporated and further Thompson 
teaches: 

- the implantable medical device comprises at least one of an implantable cardiac 
device, neural stimulation device, and drug therapy dispensing device 

(Thompson column 2 lines 39-64 teach implantable cardiac devices). 



As Per Claim 30: Claim 30 is substantially a restatement of the system of claim 1 as a 
method and is rejected under substantially the same reasoning. 
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As Per Claim 32: The rejection of claim 30 is incorporated and furtlier Claim 32 is 
substantially a restatement of the system of claim 3 as a method and is rejected under 
substantially the same reasoning. 

As Per Claim 34: The rejection of claim 30 is incorporated and further Claim 34 is 
substantially a restatement of the system of claim 5 as a method and is rejected under 
substantially the same reasoning. 

As Per Claim 35: The rejection of claim 34 is incorporated and further Claim 35 is 
substantially a restatement of the system of claim 6 as a method and is rejected under 
substantially the same reasoning. 

As Per Claim 36: The rejection of claim 35 is incorporated and further Claim 36 is 
substantially a restatement of the system of claim 7 as a method and is rejected under 
substantially the same reasoning. 

As Per Claim 37: The rejection of claim 30 is incorporated and further Claim 37 is 
substantially a restatement of the system of claim 8 as a method and is rejected under 
substantially the same reasoning. 
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As Per Claim 38: The rejection of claim 37 is incorporated and further Claim 38 is 
substantially a restatement of the system of claim 9 as a method and is rejected under 
substantially the same reasoning. 

As Per Claim 39: The rejection of claim 37 is incorporated and further Claim 39 is 
substantially a restatement of the system of claim 10 as a method and is rejected under 
substantially the same reasoning. 

As Per Claim 46: The rejection of claim 30 is incorporated and further Claim 46 is 
substantially a restatement of the system of claim 17 as a method and is rejected under 
substantially the same reasoning. 

As Per Claim 47: The rejection of claim 46 is incorporated and further Claim 47 is 
substantially a restatement of the system of claim 18 as a method and is rejected under 
substantially the same reasoning. 

As Per Claim 48: The rejection of claim 46 is incorporated and further Claim 48 is 
substantially a restatement of the system of claim 19 as a method and is rejected under 
substantially the same reasoning. 
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As Per Claim 49: The rejection of claim 48 is incorporated and further Claim 49 is 
substantially a restatement of the system of claim 20 as a method and is rejected under 
substantially the same reasoning. 

As Per Claim 56: The rejection of claim 30 is incorporated and further Claim 56 is 
substantially a restatement of the system of claim 27 as a method and is rejected under 
substantially the same reasoning. 

As Per Claim 57: The rejection of claim 30 is incorporated and further Claim 57 is 
substantially a restatement of the system of claim 28 as a method and is rejected under 
substantially the same reasoning. 

As Per Claim 58: The rejection of claim 30 is incorporated and further Claim 58 is 
substantially a restatement of the system of claim 29 as a method and is rejected under 
substantially the same reasoning. 

As Per Claim 59: Claim 59 is substantially a restatement of the system of claim 1 as an 
apparatus and is rejected under substantially the same reasoning. An apparatus 
performing the indicated function inherently has a means fordoing so. 



As Per Claim 60: Thompson teaches: 
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A system for securely transacting a data exchange session with an implantable medical 
device, comprising: 

- a short range interface device to communicate with an implantable medical 
device by authenticating access to a securely maintained crypto key using a 
short range interface; 

(Thompson, Column 8, Lines 48-59 "Key source 228 provides both programmer 
(112, 114, 116) and clinician computer 122 with encryption/decryption keys for 
encrypting/decrypting sensitive information 221. In one embodiment of the invention, 
key source 228 distributes symmetric encryption/decryption keys. In another 
embodiment of the invention, key source 228 distributes asymmetric keys (i.e., 
pubic/private keys). If the encryption/decryption algorithms employed by the invention 
are standard algorithms known to the public, additional security measures must be 
taken in the disbursement of the keys from key source 228 to programmer (112, 114, 
1 1 6) and 1 22 in order to ensure privacy."). 

- an external device to commence a data exchange session with the implantable 
medical device by transitioning to a long range interface upon successful access 
authentication, and to transact the data exchange session using the crypto key 

(Thompson, Column 9, Lines 10-16 "Before sensitive information 221 is 
transmitted across data communication media 226, sensitive information 221 is 
encrypted by encryption engine 230. Encryption engine 230 may be implemented in 
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hardware or software, although may preferably be implemented in software to allow for 
ease of upgrades to different algorithms, key lengths, and key variation."). 
(Thompson, Figure 4 
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The route for distribution of the keys by the key source (See Examiner marl< 1 
area) is the functional equivalent of the use of the "short range interface". The 
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transmission route of the encrypted data (See Examiner marl< 2 area) is the functional 
equivalent of the "long range interface". 

As Per Claim 61: The rejection of claim 60 is incorporated and further Thompson 
teaches: 

- the patient health information in maintained in an encrypted form 

(Thompson, column 10 lines 28-43, data is encrypted before exchanged). 

As Per Claim 68: The rejection of claim 60 is incorporated and further Thompson 
teaches: 

- the long range interface is augmented using one or more repeaters 

(Thompson figure 1 programmer (extender) 112 and associated text). 

As Per Claim 69: Claim 69 is substantially a restatement of the system of claim 60 as a 
method and is rejected under substantially the same reasoning. 

As Per Claim 70: The rejection of claim 69 is incorporated and further Claim 70 is 
substantially a restatement of the system of claim 61 as a method and is rejected under 
substantially the same reasoning. 
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As Per Claim 77: The rejection of claim 69 is incorporated and further Claim 77 is 
substantially a restatement of the system of claim 68 as a method and is rejected under 
substantially the same reasoning. 

As Per Claim 78: Claim 78 is substantially a restatement of the system of claim 60 as 
an apparatus and is rejected under substantially the same reasoning. An apparatus 
performing the indicated function inherently has a means fordoing so. 

As Per Claim 79: Thompson teaches: 

A system for securely transacting a data exchange session with an implantable medical 
device through secure lookup, comprising: 

- a secure external device to request the crypto key from a secure server via a 
secure connection based on the identification of and authentication to access the 
implantable medical device 

(Thompson, Column 8, Lines 48-59 "Key source 228 provides both programmer 
(112, 114, 116) and clinician computer 122 with encryption/decryption keys for 
encrypting/decrypting sensitive information 221. In one embodiment of the invention, 
key source 228 distributes symmetric encryption/decryption keys. In another 
embodiment of the invention, key source 228 distributes asymmetric keys (i.e., 
pubic/private keys). If the encryption/decryption algorithms employed by the invention 



Application/Control Number: 10/800,806 Page 23 

Art Unit: 2139 

are standard algorithms known to tine public, additional security measures must be 
taken in the disbursement of the keys from key source 228 to programmer (112, 114, 
1 1 6) and 1 22 in order to ensure privacy."). 

- to receive the crypto key, to commence a data exchange session by 
transitioning to a long range Interface upon successful access authentication 
with the Implantable medical device, and to transact the data exchange session 
using the crypto key 

(Thompson, Column 9, Lines 10-16 "Before sensitive information 221 is 
transmitted across data communication media 226, sensitive information 221 is 
encrypted by encryption engine 230. Encryption engine 230 may be implemented in 
hardware or software, although may preferably be implemented in software to allow for 
ease of upgrades to different algorithms, key lengths, and key variation."). 

(Thompson, Figure 4 
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The route for distribution of the keys by the l<ey source (See Examiner marl< 1 
area) is the functional equivalent of the use of the "secure connection". The 
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transmission route of the encrypted data (See Examiner marl< 2 area) is the functional 
equivalent of the "long range interface". 

- a securely maintained crypto key 

(Thompson, Column 8, Lines 18-50 "FIG. 4 is a block diagram illustrating one 
embodiment of a secure data transfer structural scheme in accordance with the present 
invention, shown generally at 220. In this embodiment, sensitive information 221 (such 
as patient information) is transferred in encrypted form from IMD any one of the 
programmers and instruments (112, 114, 116) or similar remote device to remote expert 
data center or clinician computer 122 across data communications media/connection 
226. While a representative use of the present invention is illustrated using 
communications between Programmer (112, 114, 116) and clinician computer 122, any 
combination of clinician devices, IMD interface devices, central database or expert 
system servers, medical device personnel personal computers or servers, and patient 
monitoring equipment, or any other data transmission device may be used in 
accordance with the present invention. In the illustrative example. Programmer (112, 
114, 116) may be any instrument capable of obtaining, storing, and transmitting medical 
and administrative information, including sensitive information 221. Programmer (112, 
114, 116) is capable of being coupled to one or more IMDs 132. IMD 132 obtains 
certain information, possibly including sensitive information 221 from the patient, then 
transfers the patient information to programmer (112, 114, 116). Data communication 
media 226 could be configured to include a telephone line connection, a direct network 
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connection, an intranet connection, an internet connection, wireless LAN, fiber optic 
network a satellite connection, a laser or infrared system, any other suitable network 
protocol connection, or a combination thereof. 

Key source 228 provides both programmer (112, 114, 116) and clinician 
computer 122 with encryption/decryption keys for encrypting/decrypting sensitive 
information 221 ."). 

A device maintaining an encryption/decryption key has a repository for it. 
Thompson does not explicitly teach the following limitation: 

- a secure server to provide identification of and authentication to access an 
implantable medical device by authenticating access to a securely maintained 
crypto key 

However Lee in analogous art does teach the above limitation: 

(Lee, Column 16 lines 3-33 Authentication is preferably implemented end to 

end.). 

It would be obvious to a person of ordinary skill in the art at the time of invention 
was made to incorporate use Lee's teachings of end to end authenticated 
communication with Thompson's method. In order to help insure that no access or 
information is unnecessarily provided to an unauthorized user. 



As Per Claim 80: Claim 80 is substantially a restatement of the system of claim 79 as a 
method and is rejected under substantially the same reasoning. 
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As Per Claim 81: Claim 81 is substantially a restatement of the system of claim 79 as 
an apparatus and is rejected under substantially the same reasoning. An apparatus 
performing the indicated function inherently has a means fordoing so. 

Claim Rejections - 35 USC § 103 

1 0. The following is a quotation of 35 U.S.C. 1 03(a) which forms the basis for all 
obviousness rejections set forth in this Office action: 

(a) A patent may not be obtained though the invention is not identically disclosed or described as set 
forth in section 102 of this title, if the differences between the subject matter sought to be patented and 
the phor art are such that the subject matter as a whole would have been obvious at the time the 
invention was made to a person having ordinary skill in the art to which said subject matter pertains. 
Patentability shall not be negatived by the manner in which the invention was made. 

1 1 . Claim 4 & 33 are rejected under 35 U.S.C. 103(a) as being unpatentable over 
Thompson in view of United States Patent No.: 6,442,432 B2 (Lee). 

As Per Claim 4: The rejection of claim 1 is incorporated and further Thompson does 
not explicitly teach the following limitations however Lee in analogous art does teach the 
following limitations: 

- a short range interface logically defining a secured area around the implantable 
medical device in which to establish the secure connection 

(Lee column 1 1 lines 3-24 and column 15 lines 38-60). 
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- a long range interface logically defining a non-secured area extending beyond 
the secured area in which to transact the data exchange session 

(Lee column 16 lines 33-49). 

It would be obvious to a person of ordinary skill in the art at the time of invention 
to use Lee's secure communication sessions with Thompson's secure connections and 
encryption methods. Lee's method of storing encrypted data on the implantable 
medical device provides specific methods of protecting sensitive data from access by 
unauthorized persons and protecting the medical device from improper snooping and 
improper instructions (Lee column 15 lines 63-67 and column 16 lines 1-4). 

As Per Claim 33: The rejection of claim 30 is incorporated and further Claim 33 is 
substantially a restatement of the system of claim 4 as a method and is rejected under 
substantially the same reasoning. 

12. Claim 11-16, 40-45, 62, 63, 65-67, 71, 72 & 74-76 are rejected under 35 U.S.C. 
103(a) as being unpatentable over Thompson in view of United States Patent No.: 
6,493,587 B1 (Eckmiller). 

As Per Claims 11 and 12: The rejection of claim 1 is incorporated and further 
Thompson does not explicitly teach the following limitations however Eckmiller in 
analogous art does teach the following limitations: 
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- the crypto key is maintained on the implantable medical device, further 
comprising: a short range telemetry interface retrieving the crypto key through 
short range telemetry 

- the short range telemetry comprises inductive telemetry 

(Eckmiller column 9 lines 28-53, passes public key). 

It would have been obvious to a person of ordinary skill in the art at the time of 
the invention to utilize Eckmillers method of storing and retrieving keys because it offers 
the advantage of preventing the unauthorized access to important functions of 
neuroprostheses and unauthorized imitation of components (Eckmiller column 3 lines 5- 
15). 

As Per Claim 13: The rejection of claim 1 1 is incorporated and further Thompson 
teaches: 

- the external device comprises a programmer 

(Thompson, Figure 4 key source 228, and column 8 lines 48-66, the key source 
distributes symmetric keys and asymmetric keys to the programmer and clinician 
computer). 



As Per Claim 14: The rejection of claim 13 is incorporated and further Thompson 
teaches: 
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- the crypto key is provided from tlie programmer to a repeater 

(Thompson, Figure 4 key source 228, and column 8 lines 48-66, tlie l<ey source 
distributes symmetric keys and asymmetric keys to the programmer and clinician 
computer; and Thompson figure 1 programmer (extender) 112 is interpreted to be the 
repeater. 

As Per Claim 15: The rejection of claim 11 is incorporated and further Thompson 
teaches: 

- the external device comprises a patient designator 

(Thompson, Figure 4 key source 228, and column 8 lines 48-66, the key source 
distributes symmetric keys and asymmetric keys to the programmer and clinician 
computer wherein the clinician computer is interpreted to be the patient designator). 

As Per Claim 16: The rejection of claim 15 is incorporated and further Thompson 
teaches: 

- the crypto key is provided from the patient designator to at least one of a 
programmer and a repeater 

(Thompson, Figure 4 key source 228, and column 8 lines 48-66, the key source 
distributes symmetric keys and asymmetric keys to the programmer and clinician 
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computer; within the asymmetric key algorithm the public key would be passed from the 
clinician computer to the programmer). 

As Per Claims 40^5: The rejection of claim 30 is incorporated and further Claims 40- 
45 are substantially a restatement of the systems of claims 1 1-16 as a method and are 
rejected under substantially the same reasoning. 

As per Claim 62: The rejection of claim 60 is incorporated and further Thompson does 
not explicitly teach the following limitation however Eckmiller in analogous art does 
teach the following limitation: 

- the authenticating with the implantable medical device is through short range 

telemetry, further comprising: a short range telemetric connection with the 
implantable medical device; a short range telemetric device to request the crypto 
key from the implantable medical device, and to receive the crypto key from the 
implantable medical device 

(Eckmiller column 9 lines 28-53, passes public key). 

It would have been obvious to a person of ordinary skill in the art at the time of 
the invention to utilize Eckmillers method of storing and retrieving keys because it offers 
the advantage of preventing the unauthorized access to important functions of 
neuroprostheses and unauthorized imitation of components (Eckmiller column 3 lines 5- 
15). 
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As per Claim 63: The rejection of claim 60 is incorporated and furtlier Tliompson 
teaches: 

- a patient designator to request the crypto key from the implantable medical 
device, and to receive the crypto key from the implantable medical device 

(Thompson, Figure 4 l<ey source 228, and column 8 lines 48-66, the key source 
distributes symmetric keys and asymmetric keys to the programmer and clinician 
computer wherein the clinician computer is interpreted to be the patient designator). 

Thompson does not explicitly teach the following limitation however Eckmiller in 
analogous art does teach the following limitation: 

- a short range telemetric connection with the implantable medical device 

(Eckmiller column 9 lines 28-53, passes public key). 

It would have been obvious to a person of ordinary skill in the art at the time of 
the invention to utilize Eckmillers method of storing and retrieving keys because it offers 
the advantage of preventing the unauthorized access to important functions of 
neuroprostheses and unauthorized imitation of components (Eckmiller column 3 lines 5- 
15). 
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As per Claim 65: The rejection of claim 60 is incorporated and further Thompson does 
not explicitly teach the following limitation however Eckmiller in analogous art does 
teach the following limitation: 

- the patient liealtli information is maintained in the implantable medical device in 
unencrypted form and is accessible in the unencrypted form exclusively through 
a short range telemetric connection 

(Eckmiller column 9 lines 28-53, passes public key). 

It would have been obvious to a person of ordinary skill in the art at the time of 
the invention to utilize Eckmillers method of storing and retrieving keys because it offers 
the advantage of preventing the unauthorized access to important functions of 
neuroprostheses and unauthorized imitation of components (Eckmiller column 3 lines 5- 
15). 

As per Claim 66: The rejection of claim 65 is incorporated and further Thompson 
teaches: 

- an external source to send a session crypto key to the implantable medical 
device 

(Thompson, Figure 4 key source 228, and column 8 lines 48-66, the key source 
distributes symmetric keys and asymmetric keys to the programmer and clinician 
computer wherein the clinician computer is interpreted to be the patient designator); and 
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- an encrypter to encrypt the patient health information maintained in the 
implantable medical device 

(Thompson, Figure 4 botli the Programmer and the Clinician computer have 
encryption engines and decryption engines). 

Thompson does not explicitly teach the following limitation however Eckmiller in 
analogous art does teach the following limitation: 

- a short range telemetric connection with the Implantable medical device 

(Eckmiller column 9 lines 28-53, passes public key). 

It would have been obvious to a person of ordinary skill in the art at the time of 
the invention to utilize Eckmillers method of storing and retrieving keys because it offers 

the advantage of preventing the unauthorized access to important functions of 
neuroprostheses and unauthorized imitation of components (Eckmiller column 3 lines 5- 
15). 

As per Claim 67: The rejection of claim 60 is incorporated and further Thompson 
teaches: 

- an encrypter to encrypt the patient health information maintained in the 
implantable medical device 
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(Thompson, Figure 4 botli tine Programmer and the Clinician computer have 
encryption engines and decryption engines). 

Thompson does not explicitly teach the following limitation however Eckmiller in 
analogous art does teach the following limitation: 

- a patient designator to establish a short range telemetric connection with the 
implantable medical device, and to send a session crypto key to the implantable 
medical device 

(Eckmiller column 9 lines 28-53, passes public key) 

As Per Claim 71: The rejection of claim 69 is incorporated and further Claim 71 is 
substantially a restatement of the systems of claim 62 as a method and is rejected 
under substantially the same reasoning. 

As Per Claim 72: The rejection of claim 69 is incorporated and further Claim 72 is 
substantially a restatement of the systems of claim 63 as a method and is rejected 
under substantially the same reasoning. 

As Per Claim 74: The rejection of claim 69 is incorporated and further Claim 74 is 
substantially a restatement of the systems of claim 65 as a method and is rejected 
under substantially the same reasoning. 
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As Per Claim 75: The rejection of claim 74 is incorporated and further Claim 75 is 
substantially a restatement of the systems of claim 66 as a method and is rejected 
under substantially the same reasoning. 

As Per Claim 76: The rejection of claim 69 is incorporated and further Claim 76 is 
substantially a restatement of the systems of claim 67 as a method and is rejected 
under substantially the same reasoning. 

13. Claim 21-26, 50-55, 64 & 73 are rejected under 35 U.S.C. 103(a) as being 
unpatentable over Thompson in view of United States Patent Application Publication 
No.: 2002/0016913 A1 (Wheeler et al.). 

As Per Claim 21: The rejection of claim 1 is incorporated and further Thompson does 
not explicitly teach the following limitations however Wheeler et al in analogous art does 
teach the following limitations: 

- a physical token to maintain the crypto key; and a reader to retrieve the crypto 
key by accessing the physical token 

(Wheeler et al.. Paragraphs [0066] and [0279]). 

It would have been obvious to one of ordinary skill in the art at the time of 
invention was made to incorporate Wheeler et al.'s use of a smart card in to 
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Thompson's method. In order to enhance the level of security provided in Thompson's 
method. 

As Per Claim 22: The rejection of claim 21 is incorporated and further Thompson does 
not explicitly teach the following limitations however Wheeler et al in analogous art does 
teach the following limitations: 

- a physical label to specify the crypto key on the physical token 

(Wheeler et al., Paragraphs [0066] and [0279]). 

It would have been obvious to one of ordinary skill in the art at the time of 
invention was made to incorporate Wheeler et al.'s use of a smart card in to 
Thompson's method. In order to enhance the level of security provided in Thompson's 
method. 

As Per Claim 23: The rejection of claim 22 is incorporated and further Thompson does 
not explicitly teach the following limitations however Wheeler et al in analogous art does 
teach the following limitations: 

- the physical label comprises at least one of alphanumeric text, bar coding, and 
an outwardly-appearing indication 

(Wheeler et al., Paragraphs [0066] and [0279]). 
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It would have been obvious to one of ordinary skill in the art at the time of 
invention was made to incorporate Wheeler et al.'s use of a smart card in to 
Thompson's method. In order to enhance the level of security provided in Thompson's 
method. 

As Per Claim 24: The rejection of claim 21 is incorporated and further Thompson does 
not explicitly teach the following limitations however Wheeler et al in analogous art does 
teach the following limitations: 

- internal storage to specify the crypto key on the physical token 

(Wheeler et al., Paragraphs [0066] and [0279]). 

It would have been obvious to one of ordinary skill in the art at the time of 

invention was made to incorporate Wheeler et al.'s use of a smart card in to 
Thompson's method. In order to enhance the level of security provided in Thompson's 
method. 

As Per Claim 25: The rejection of claim 24 is incorporated and further Thompson does 
not explicitly teach the following limitations however Wheeler et al in analogous art does 
teach the following limitations: 
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- the internal storage comprises at least one of a transistor, a memory circuit, an 
electronically readable storage medium, and a magnetically readable storage 
medium 

(Wheeler et al., Paragraphs [0066] and [0279]). 

It would have been obvious to one of ordinary skill in the art at the time of 
invention was made to incorporate Wheeler et al.'s use of a smart card in to 
Thompson's method. In order to enhance the level of security provided in Thompson's 
method. 

As Per Claim 26: The rejection of claim 21 is incorporated and further Thompson does 
not explicitly teach the following limitations however Wheeler et al in analogous art does 
teach the following limitations: 

- the physical token is accessed using magnetic, optical, serial, and physical 
reading 

(Wheeler et al., Paragraphs [0066] and [0279]). 

It would have been obvious to one of ordinary skill in the art at the time of 
invention was made to incorporate Wheeler et al.'s use of a smart card in to 
Thompson's method. In order to enhance the level of security provided in Thompson's 
method. 



Application/Control Number: 10/800,806 Page 40 

Art Unit: 2139 

As Per Claims 50-55: The rejection of claim 30 is incorporated and further Claims 50- 
55 are substantially a restatement of the systems of claims 21-26 as a method and are 
rejected under substantially the same reasoning. 

As Per Claim 64: The rejection of claim 60 is incorporated and further Thompson does 
not explicitly teach the following limitations however Wheeler et al in analogous art does 
teach the following limitations: 

- the authenticating with the implantable medical device is by using a physical 
token, further comprising: a physical token; and a reader to receive the crypto 
key from the physical token 

(Wheeler et al., Paragraphs [0066] and [0279]). 

It would have been obvious to one of ordinary skill in the art at the time of 
invention was made to incorporate Wheeler et al.'s use of a smart card in to 
Thompson's method. In order to enhance the level of security provided in Thompson's 
method. 

As Per Claim 73: The rejection of claim 69 is incorporated and further Claim 73 is 
substantially a restatement of the system of claim 64 as a method and is rejected under 
substantially the same reasoning. 
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Conclusion 

14. THIS ACTION IS MADE FINAL. Applicant is reminded of tine extension of time 
policy as set forth in 37 CFR 1 .136(a). 

A shortened statutory period for reply to this final action is set to expire THREE 
MONTHS from the mailing date of this action. In the event a first reply is filed within 
TWO MONTHS of the mailing date of this final action and the advisory action is not 
mailed until after the end of the THREE-MONTH shortened statutory period, then the 
shortened statutory period will expire on the date the advisory action is mailed, and any 
extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of 
the advisory action. In no event, however, will the statutory period for reply expire later 
than SIX MONTHS from the mailing date of this final action. 

Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to BENJAMIN A. KAPLAN whose telephone number is 
(571)270-3170. The examiner can normally be reached on 7:30 a.m. - 5:00 p.m. E.S.T.. 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, Kristine Kincaid can be reached on 571-272-4063. The fax phone number 
for the organization where this application or proceeding is assigned is 571-273-8300. 
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Information regarding the status of an application may be obtained from the 
Patent Application Information Retrieval (PAIR) system. Status information for 
published applications may be obtained from either Private PAIR or Public PAIR. 
Status information for unpublished applications is available through Private PAIR only. 
For more information about the PAIR system, see http://pair-direct.uspto.gov. Should 
you have questions on access to the Private PAIR system, contact the Electronic 
Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a 
USPTO Customer Service Representative or access to the automated information 
system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. 

Benjamin Kaplan 
/Kristine Kincaid/ 

Supervisory Patent Examiner, Art Unit 2139 



